Impact
Ghost 4.3.0 through 6.57.x contains an authorization flaw where staff users with lower privileges can use staff tokens to edit posts beyond their allowed scope. This allows an attacker who has staff credentials or can obtain a staff token to perform unauthorized content modifications, compromising the integrity of published articles and potentially facilitating defacement or misinformation.
Affected Systems
The vulnerability is present in Ghost CMS products distributed by TryGhost, specifically Ghost versions 4.3.0 up to 6.57.x. Versions 6.58.0 and newer contain the fix. Organizations running these older releases are at risk if staff tokens are enabled and staff privileges are assigned.
Risk and Exploitability
With a CVSS score of 5.3 the severity is moderate, and the lack of an EPSS score or KEV listing indicates no known exploitation of this flaw yet. The most likely attack vector is via staff tokens, meaning an adversary with staff credentials or the ability to acquire a staff token can bypass editing restrictions. The flaw does not require elevation beyond staff roles, so the primary impact is on content integrity rather than full system compromise.
OpenCVE Enrichment